Short answer: choose an ISO 27001 certification body that is accredited by a recognised national accreditation body, has real experience in your sector and at your company size, has the capacity to meet your timeline, and is impartial toward your business. Accreditation and impartiality are the two things you should verify before price. This guide walks through each, and shows you how to compare firms and get comparable quotes without chasing five inboxes.
Getting ISO 27001 certified is usually the moment a stalled deal, a renewal, or a funding round starts moving again. The certificate matters, but so does who signs it. An accredited, well matched, genuinely independent auditor makes the process smoother and the certificate more credible to the customer asking for it. A poor fit can cost you months and, occasionally, a re-audit. This guide will help you choose well, and it stays neutral throughout. Nomona does not perform audits and takes no position on which firm you pick.
What is an ISO 27001 auditor?
The firm that issues your ISO 27001 certificate is called a certification body (CB). It assesses your information security management system (ISMS) against the ISO/IEC 27001 standard and, if you meet it, issues the certificate. This is not the same as a consultant or a compliance platform. A consultant helps you get ready; a platform helps you collect and manage evidence. The certification body is the independent party that examines your management system and certifies it, and it must stay at arm's length from the other two.
That independence is not a nice-to-have. It is written into the rules certification bodies operate under.
Why accreditation is the first thing to verify
Anyone can print a certificate. What gives an ISO 27001 certificate its weight is that the certification body behind it is accredited. Accreditation means an independent national authority has assessed the certification body itself against the international standard for certification bodies, ISO/IEC 17021-1, and confirmed it is competent and impartial.
Accreditation bodies are national and sit under the International Accreditation Forum (IAF). Examples include UKAS in the United Kingdom, the RvA in the Netherlands, DAkkS in Germany, COFRAC in France, and ANAB in the United States. A certificate from an accredited body is the one your enterprise customers will recognise. A certificate from an unaccredited body can be cheaper and faster, and it can also be waved away by the exact customer you got certified for, which defeats the point of doing it.
How to verify accreditation in two minutes: ask the certification body which accreditation body accredits it and for which scheme, then check that accreditation body's public register, or search the IAF CertSearch database. If a firm cannot answer this clearly, treat it as a red flag.
How to compare accredited auditors on fit
Once you have a shortlist of accredited firms, fit is what separates them. Four things to weigh:
Sector and size experience. An auditor who regularly certifies B2B SaaS companies of your size will already understand your architecture, your cloud setup, and the controls that actually matter for you. One who mostly works with manufacturers or hospitals will spend your time getting up to speed. Ask how many organisations like yours they have certified in the last year.
Scope match. Be clear about what you are certifying: which products, which entities, which locations, and how your use of cloud infrastructure and subprocessors is treated. A good auditor helps you define a scope that is honest and defensible, not one inflated to raise the fee.
Capacity and timeline. Auditors get booked out, sometimes months ahead. If a customer contract depends on your certificate landing by a set date, capacity matters as much as competence. Confirm real availability before you get attached to a firm.
Communication. You will work closely with this firm for weeks, and then annually for years. How responsive and clear they are during the quote stage is a fair preview of the engagement itself.
How much does an ISO 27001 audit cost?
Real numbers help, so here are planning ranges. Initial certification with an accredited body typically starts upwards of €5,000 for a small company (up to roughly 50 people) and commonly lands between €5,000 and €15,000. Larger or multi-site scopes often run €15,000 to €40,000 or more. On top of the initial certificate, budget for annual surveillance audits across the three-year cycle, usually around a third to a half of the initial fee each year. Treat these as planning ranges, not a quote.
The fee is driven mainly by audit days, which follow from your headcount and scope, so keeping your scope honest and comparing more than one firm are the two things that most move your budget. For the same scope, quotes vary more than most buyers expect. For a number specific to your company, request quotes from accredited firms rather than relying on a published range.
What does the ISO 27001 certification process look like?
ISO 27001 certification follows a defined path, and knowing it up front helps you plan.
- Readiness. You build and run your information security management system, usually for a few months, so there is evidence to assess. Many companies use a consultant or a compliance platform here.
- Stage 1 audit. The certification body reviews your documentation and readiness and flags gaps before the main event.
- Stage 2 audit. The main assessment, where the auditor examines whether your management system is implemented and effective.
- Certification decision. If you pass, the body issues a certificate that is valid for three years.
- Surveillance and recertification. The body conducts surveillance audits, typically annually, and a full recertification at the end of the three-year cycle.
From a ready starting point, getting from Stage 1 to a certificate often takes around 4 to 8 weeks for a small company, and longer for larger or multi-site scopes, depending on findings and the firm's availability. Build in buffer if a customer deadline is riding on it.
The independence question most buyers skip
Certification bodies are bound by ISO/IEC 17021-1 clause 5.2, which requires them to be impartial and to identify and manage anything that threatens that impartiality. Under it, a certification body cannot certify an organisation to which it also provided the consultancy that got it ready (clause 5.2.5). The rule exists for a simple reason: a certifier with a stake in the outcome is not really certifying.
Worth keeping in mind when another party hands you a shortlist of auditors, such as a consultant or a compliance platform you already use. Convenience is real, and a recommended auditor can be an excellent choice. The point is only to check that the recommendation is about fit rather than a commercial arrangement you cannot see. You are allowed to ask.
Three questions to keep your choice independent:
- Does whoever recommended this auditor receive any compensation or commercial benefit tied to the recommendation?
- Who sets the audit fee and scope, the auditor using their own professional judgement, or a third party?
- Am I free to choose an auditor who is not on the recommended list?
If you are pursuing SOC 2 rather than ISO 27001, the same principle applies under different rules. SOC 2 is an AICPA attestation, so the AICPA's independence and referral-fee rules govern it. The AICPA's own publication, the Journal of Accountancy, examined these exact arrangements in April 2026 in an article on the ethics risks of referral fees from tool providers. The questions to ask are the same.
How to compare ISO 27001 firms and get quotes
Once accreditation is verified, fit is clear, and independence checks out, what is left is comparison. Most companies want to see more than one quote before committing, partly on price and partly for internal spend approval. Getting there usually means tracking down accredited firms, working out which are a genuine fit, and emailing each one separately.
That last part is what Nomona is built to remove. Nomona is an independent marketplace and trust registry for security and compliance auditors. You can compare accredited firms on fit and verified reviews, then send one structured request to receive comparable quotes rather than chasing several inboxes. Nomona does not perform audits and does not take a cut for steering you toward any particular firm; results are ordered by fit.
To start, browse accredited ISO 27001 firms in the registry, or post a single request and let matched firms come back to you with quotes.
Frequently asked questions
- Do I have to use an accredited certification body for ISO 27001?
- It is not legally mandatory, but an accredited certificate is what your customers and partners are asking for. An unaccredited certificate can be rejected by the very buyer you certified for, so accreditation is the safer choice in almost every commercial situation.
- How do I check if an ISO 27001 certification body is accredited?
- Ask which national accreditation body accredits them and for which scheme, then confirm it on that accreditation body's public register or through the IAF CertSearch database. Accreditation bodies include UKAS, RvA, DAkkS, COFRAC, and ANAB.
- How much does an ISO 27001 audit cost?
- It depends mostly on company size, scope, and region, and commonly ranges from a few thousand to the low tens of thousands of euros for small and mid-sized companies. Because pricing for the same scope varies between firms, comparing more than one quote is the most reliable way to understand your real cost.
- How long does ISO 27001 certification take?
- From a ready starting point, the Stage 1 to certificate path often takes a few weeks to a couple of months, depending on audit findings and the certification body's availability. The certificate is then valid for three years, with annual surveillance audits.
- What is the difference between an ISO 27001 auditor and a consultant?
- A consultant helps you build and prepare your information security management system. The auditor, formally the certification body, independently assesses that system and issues the certificate. They must be separate parties, because a firm cannot impartially certify work it also did for you.
- Can my consultant or compliance platform also be my auditor?
- No. Under ISO/IEC 17021-1 clause 5.2, a certification body cannot certify an organisation it also provided consultancy to, because that would compromise its impartiality. A consultant or platform can help you get ready, but the certifying body must be independent.
- What questions should I ask before choosing an ISO 27001 auditor?
- Ask which accreditation body accredits them and for which scheme, how many companies of your size and sector they certified in the last year, what scope and how many audit days they propose, and their real availability against your deadline. If someone recommended them, ask whether that recommendation carries any commercial benefit.
- Is it a problem if my compliance platform recommends an auditor?
- Not necessarily. A recommended auditor can be a genuinely good fit. It is reasonable to check that the recommendation is based on fit rather than an undisclosed commercial arrangement, by asking who benefits from the recommendation, who sets the fee, and whether you are free to choose off-list.
Related reading
- GuideHow to Choose a SOC 2 Auditor
Why a SOC 2 report has to come from a CPA firm, how Type 1 and Type 2 differ, and how to compare quotes without buying on price alone.
- For AuditorsHow audit firms get more clients in 2026 (without buying placement)
Where compliance audit firms actually find new clients in 2026, why platform partner programs squeeze independent firms, and how to win engagements on merit.
- Buying guideHow much does a SOC 2 audit cost in 2026? A buyer's breakdown
A transparent breakdown of what a SOC 2 audit actually costs in 2026: readiness, Type I, Type II, and ongoing surveillance, plus how to get an itemized quote you can trust.